kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://github.com/sg-summer/cve/issues/3 |
Configurations
No configuration.
History
16 Sep 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 18:17
Updated : 2026-09-16 18:17
NVD link : CVE-2026-88593
Mitre link : CVE-2026-88593
CVE.ORG link : CVE-2026-88593
JSON object : View
Products Affected
No product.
CWE
No CWE.
